Threat actors are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with more than 6,000 active installations, to upload PHP web shells and gain remote code execution on affected sites.

The flaw, tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier. It was discovered by security researcher Teemu Saarentaus and is an unauthenticated arbitrary file-upload vulnerability. The issue stems from an exposed AJAX action called wwlc_file_upload_handler, which validates uploaded file extensions against an allowlist supplied via a user-controlled request parameter named file_settings. Because the allowlist is client-supplied, an attacker can simply add “php” to the list of permitted file types, tricking the plugin into accepting executable PHP files.

Active Exploitation

WordPress security firm Wordfence, part of Defiant, says its web application firewall has blocked more than 100,000 attacks tied to this vulnerability. Exploitation activity spiked in distinct waves between June 4 and June 17, and again on July 1 and August 30.

According to Wordfence, attackers send a forged file_settings parameter alongside a malicious .php file to the wwlc_file_upload_handler endpoint. The resulting payload, typically named shell.php, functions as a full-featured web shell: it reports host details back to the attacker and provides a browser-based interface for uploading additional malicious files, enabling further compromise or lateral movement.

Patch and Mitigation

The vendor fixed the vulnerability in version 2.0.3.2, released on February 20. Despite the patch being available for months, exploitation has continued at scale, underscoring how slowly some WordPress site operators apply plugin updates.

Wordfence has published a list of high-offender IP addresses responsible for tens of thousands of exploitation attempts and recommends administrators add these to a blocklist immediately.

  • Upgrade WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later
  • Inspect upload directories for unexpected or recently created PHP files
  • Review server logs for requests to /wp-admin/admin-ajax.php invoking wwlc_file_upload_handler
  • Audit for and remove unknown or unauthorized administrator accounts

If compromise is confirmed, Wordfence recommends restoring the site from a known-safe backup rather than attempting manual cleanup, since fully removing persistence mechanisms, rogue accounts, and backdoors can be difficult to verify.